Page 2 of 4

Re: THE FORUM HAS BEEN HACKED (AND FIXED, AND MOVED TO A NEW SERVER) - PLEASE READ CAREFULLY

Posted: Fri Apr 21, 2017 7:57 am
by neofight78
emk and rdearman are heros, thanks so much guys! Happy to chip in with server costs or any other way I can, just let me know how.

Re: THE FORUM HAS BEEN HACKED (AND FIXED, AND MOVED TO A NEW SERVER) - PLEASE READ CAREFULLY

Posted: Fri Apr 21, 2017 9:08 am
by zenmonkeyII
Thanks again for this work and the overall effort to keep this place running. Not only did you guys fix the issues but did it very quickly! A beer for each!

As has been mentioned password recovery does not send out the email - it is likely a configuration option on the email function.

Also note that the logon is not secured - password and email seem to be sent over an unsecured regular http connection.

Re: THE FORUM HAS BEEN HACKED (AND FIXED, AND MOVED TO A NEW SERVER) - PLEASE READ CAREFULLY

Posted: Fri Apr 21, 2017 10:05 am
by emk
zenmonkeyII wrote:As has been mentioned password recovery does not send out the email - it is likely a configuration option on the email function.

Yeah, email from the forum appears to be broken still. We'll figure it out. I'm guessing that whatever SMTP server we used doesn't like the new setup.

Update: Our SMTP configuration hasn't changed. The forum is trying to send emails, but they're not making it through. To fix this, we'll probably have to pay somebody with an SMTP server to send them on our behalf. AWS SES can do this, I think.

zenmonkeyII wrote:Also note that the logon is not secured - password and email seem to be sent over an unsecured regular http connection.

Yes, we've never paid for or configured an HTTPS certificate for the site. I'd like to fix that, but actually getting it to work is going to require some more effort on the back end. Probably we'll go with LetsEncrypt and some kind of automatic renewal system, because that's free. Or maybe the new AWS cert system, if it's automatic enough.

Are you the same zenmonkey as usual? Did you have trouble recovering access to your old account for some reason? If so, I believe I have your email address somewhere and I'm happy to work with you to confirm your identity and fix this.

Re: THE FORUM HAS BEEN HACKED (AND FIXED, AND MOVED TO A NEW SERVER) - PLEASE READ CAREFULLY

Posted: Fri Apr 21, 2017 10:22 am
by PeterMollenburg
Others have said it already, so apologies for the repetition, but thank you very much indeed rdearman and emk, for your tireless work on our behalf in order to protect our information and keep our awesome community running... and even improving.

Re: THE FORUM HAS BEEN HACKED (AND FIXED, AND MOVED TO A NEW SERVER) - PLEASE READ CAREFULLY

Posted: Fri Apr 21, 2017 11:52 am
by iguanamon
If we ever needed a reminder of why we left HTLAL, here it is. Nobody likes outages, but they happen from time to time. The difference here at LLORG is:

1) The administrators communicated with us
2) The administrators fixed the problem in a timely manner

This didn't happen at our former home in the same way as here... which is why we moved.

Obrigado, valeu, gracias, mèsi anpil, mersi muncho, thank you rdearman and emk!

Re: THE FORUM HAS BEEN HACKED (AND FIXED, AND MOVED TO A NEW SERVER) - PLEASE READ CAREFULLY

Posted: Fri Apr 21, 2017 12:24 pm
by zenmonkeyII
emk wrote:Are you the same zenmonkey as usual? Did you have trouble recovering access to your old account for some reason? If so, I believe I have your email address somewhere and I'm happy to work with you to confirm your identity and fix this.


Yep, same person. Creates this account as I did a password change and the site isn't accepting my old or new one but I suspect a chair/desk interface issue. I'll wait until the mail recovery works and go from there. Don't worry about the time needed to get my ident and fix this - this is a sufficient workaround until the email server is up again.

Re: THE FORUM HAS BEEN HACKED (AND FIXED, AND MOVED TO A NEW SERVER) - PLEASE READ CAREFULLY

Posted: Fri Apr 21, 2017 12:50 pm
by zenmonkeyII
emk wrote:Are you the same zenmonkey as usual? Did you have trouble recovering access to your old account for some reason? If so, I believe I have your email address somewhere and I'm happy to work with you to confirm your identity and fix this.


Yes it is me, but don't worry about it. I can work with this until the email server is up and running. Thanks.

Re: THE FORUM HAS BEEN HACKED (AND FIXED, AND MOVED TO A NEW SERVER) - PLEASE READ CAREFULLY

Posted: Fri Apr 21, 2017 1:37 pm
by Ingaræð
Fantastic job, guys! Thank you so much for putting in the time and effort, and getting things sorted so quickly. :)

EDIT: Oh, and thanks for the answer about the email addresses.

Re: THE FORUM HAS BEEN HACKED (AND FIXED, AND MOVED TO A NEW SERVER) - PLEASE READ CAREFULLY

Posted: Fri Apr 21, 2017 1:59 pm
by tomgosse
iguanamon wrote:If we ever needed a reminder of why we left HTLAL, here it is. Nobody likes outages, but they happen from time to time. The difference here at LLORG is:

1) The administrators communicated with us
2) The administrators fixed the problem in a timely manner

This didn't happen at our former home in the same way as here... which is why we moved.

Obrigado, valeu, gracias, mèsi anpil, mersi muncho, thank you rdearman and emk!

And we are not left wandering blindly as we were at the old place. :lol:

Re: THE FORUM HAS BEEN HACKED (AND FIXED, AND MOVED TO A NEW SERVER) - PLEASE READ CAREFULLY

Posted: Fri Apr 21, 2017 5:02 pm
by jeff_lindqvist
Yeah, great job, Rdearman and Emk! I hadn't noticed that the forum was down until I was going to show it to one of our patrons at the library:
-I'll forward your question to the experts on the #1 language forum... have a look here... oops it's been hacked. :?